Lucene search

K

FuturioWP Security Vulnerabilities

cve
cve

CVE-2024-5646

The Futurio Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘header_size’ attribute within the Advanced Text Block widget in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated....

6.4CVSS

5.7AI Score

0.001EPSS

2024-06-11 09:15 PM
23
cve
cve

CVE-2023-40201

Cross-Site Request Forgery (CSRF) vulnerability in FuturioWP Futurio Extra plugin <= 1.8.4 versions leads to activation of arbitrary...

8.8CVSS

8.8AI Score

0.001EPSS

2023-10-03 01:15 PM
23
cve
cve

CVE-2021-25110

The Futurio Extra WordPress plugin before 1.6.3 allows any logged in user, such as subscriber, to extract any other user's email...

4.3CVSS

4.5AI Score

0.001EPSS

2022-02-14 12:15 PM
56
cve
cve

CVE-2021-25109

The Futurio Extra WordPress plugin before 1.6.3 is affected by a SQL Injection vulnerability that could be used by high privilege users to extract data from the database as well as used to perform Cross-Site Scripting (XSS) against logged in admins by making send open a malicious...

2.7CVSS

3.8AI Score

0.001EPSS

2022-02-14 12:15 PM
63